Incorrect authorization in imgcrypt - CVE-2022-24778

 

Incorrect authorization in imgcrypt - CVE-2022-24778

Published: June 27, 2022 / Updated: June 28, 2022


Vulnerability identifier: #VU64699
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24778
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists in imgcrypt library when checking the keys of an authorized user to access an encrypted image on systems where layers are not available and cannot run on the host architecture. A remote attacker can run an image without providing the previously decrypted keys and gain access to sensitive information.


Affected software

imgcrypt
Red Hat Advanced Cluster Security for Kubernetes
IBM Concert Software
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Transformation Advisor
IBM Edge Application Manager
Ubuntu
Fedora
golang-github-containerd-imgcrypt
containerd (Ubuntu package)
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2022-24778

Install updates from vendor's website.

imgcrypt - update to 1.1.4
Red Hat Advanced Cluster Security for Kubernetes - update to 3.73
IBM Concert Software - update to 1.0.1
golang-github-containerd-imgcrypt - addressed in versions 1.1.4-1.fc34, 1.1.4-1.fc35, 1.1.4-1.fc36, 1.1.4-1.fc37
containerd (Ubuntu package) - addressed in versions 1.5.9-0ubuntu1~18.04.2, 1.5.9-0ubuntu1~20.04.6, 1.5.9-0ubuntu3.1, 1.6.4-0ubuntu1.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.3, 2.5.0
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0

External References

Related Security Bulletins